How to Choose a CREST Pen-Test Provider: 12-Point Checklist for CISOs & Procurement
We’ve been on both sides — buyer and tester. Here’s what actually matters.
Hook: Copy-paste this checklist into your RFP. If a vendor fails 3+ points, walk away — you’re buying a scanner report, not assurance.
The Enterprise Checklist (Score 1-5, 12 = Pass)
1. CREST Company Accreditation — prove it. Ask for CREST membership number + expiry. Verify at crest-approved.org. 2. Tester Certs — CRT/CCT, not “5 years experience”. Ask for anonymized CVs with CREST IDs. 3. Methodology — CREST + OWASP ASVS 4.0 + NIST SP 800-115? No methodology doc = ad-hoc. 4. Scoping Workshop Included? 90 min with your engineers — or they’ll miss authz flaws. 5. Rules of Engagement & NDA? Out-of-scope protection + data handling + retention. 6. Manual > Scanner? What % is manual? <30% manual = false-positive dump. 7. Kill-Chain Narrative? Do they show how they chained 3 lows into domain admin? 8. Risk Rating — CVSS + OWASP Risk? CVSS alone lies about business impact. 9. Compliance Mapping? ISO 27001 / SOC 2 / PCI DSS / GDPR mapping in report? 10. Remediation Retest Included? Free retest within 30 days — or you pay twice. 11. Board-Ready Executive Summary? 2-page risk summary a non-technical board gets. 12. Clear Scope & 10-Day SLA? No day-rate surprises, no 6-week wait.
Red Flags: “We can start tomorrow with no scoping,” “One tester for all apps,” “No sample report,” “Day-rate billing.”
The Snipeyes Answer
We score 12/12 by default: CREST-accredited, ISO 27001 certified — the boring part that lets you trust the exciting part, CRT/CCT team, CREST methodology, 90-min scoping, NDA, 70% manual, kill-chain, OWASP Risk Rating, 5-framework mapping, free retest, 2-page exec summary, 10-day report.
Lead Magnet: [Download PDF: 12-Point CREST Vendor Scorecard + RFP Template →] Print it. Use it. Send us the scored sheet — we’ll honor the lowest credible bid + beat the SLA.
CTA: Get Sample CREST Report + Scorecard Review — Free → · See Our CREST Methodology →
Quick self-test: Calculate Your OWASP Risk Rating →